maclasse2025[.]fr
“Ma Classe 2025”
Résumé des preuves
Analysis of maclasse2025.fr, created on February 21 2026, shows a short‑lived infrastructure that was taken offline prior to the report date of July 24 2026. The domain resolves to IP address 188.114.97.3, which is hosted by Cloudflare (AS13335) and geolocated to the United States. DNS data lists ns1.amenworld.com and ns2.amenworld.com as authoritative nameservers, and the MX record points to mail-fr.securemail.pro with a priority of 10, suggesting a functional mail set‑up that could have been used for credential harvesting. The site presented the page title "Ma Classe 2025" and was served over an SSL certificate identified as WE1, indicating that TLS was provisioned despite the brief operational window.
Reputation signals are mixed: the domain appears on a single security blocklist and is actively blocked by the PhishDestroy service. VirusTotal scans recorded four positive detections out of ninety‑five antivirus engines, confirming that at least a subset of security products flagged the site as malicious. The limited exposure, recent registration, and rapid takedown are consistent with a targeted generic phishing campaign.
Uncertainty remains around the exact phishing kit employed and any secondary payloads that may have been delivered before the site was taken offline, as no additional forensic artifacts have been disclosed. Defenders should continue to block the domain and its associated IP address at perimeter and endpoint layers, monitor for any resurgence of the same nameserver or MX configurations, and consider adding the observed MX host to email filtering rules. Ongoing threat‑intel feeds should be consulted for any re‑use of the Cloudflare IP range in similar campaigns, and incident response teams should verify that no credentials from the "Ma Classe 2025" theme have been compromised in their environment.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 13/08/2026
10 sources externes surveillées Aucune correspondance
Analyse forensique
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif